{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T19:13:15Z","timestamp":1782846795559,"version":"3.54.5"},"reference-count":32,"publisher":"Association for Computing Machinery (ACM)","issue":"FSE","license":[{"start":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T00:00:00Z","timestamp":1782777600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"funder":[{"DOI":"10.13039\/501100001711","name":"SNSF","doi-asserted-by":"crossref","award":["CEGP2 186974"],"award-info":[{"award-number":["CEGP2 186974"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100001711","name":"SNSF","doi-asserted-by":"crossref","award":["00021- 236559"],"award-info":[{"award-number":["00021- 236559"]}],"id":[{"id":"10.13039\/501100001711","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Proc. ACM Softw. Eng."],"published-print":{"date-parts":[[2026,6,30]]},"abstract":"<jats:p>\n                    Scripting languages like Python, Ruby, or PHP are integral to modern software development. Despite security measures like memory safety and sandboxing, vulnerabilities within these engines can lead to critical issues such as remote code execution or sandbox escapes. A particularly pervasive class of vulnerabilities is\n                    <jats:italic toggle=\"yes\">callback bugs<\/jats:italic>\n                    , which occur when user-defined callbacks violate runtime invariants, such as freeing an object still in use (can be reached through live pointers) or modifying a data structure during traversal. These violations can result in severe consequences, including use-after-free, null-pointer dereferences, and type confusion, often leading to crashes, memory corruption, or even exploitable vulnerabilities. Detecting callback bugs remains challenging due to a lack of general understanding, as they have not been formally characterized or systematically studied. As such, existing tools lack the ability to (1) establish clear links between script-side callbacks and their native-side invokers, and (2) generate scripts that systematically satisfy preconditions required to trigger these bugs.\n                  <\/jats:p>\n                  <jats:p>We propose CrossFit, a novel 2-tier approach combining static analysis and targeted fuzzing to systematically discover callback bugs. CrossFit first establishes links between script-side callbacks and their native-side invokers through context link analysis, enabling targeted exploration of high-risk code paths. It then generates proof-of-concept scripts with custom classes and magic methods, introducing side-effect operations to violate runtime invariants. Our evaluation shows that CrossFit effectively outperforms existing tools by up to 12.04% in terms of callsite coverage (i.e., potential sites where callback bugs may occur). We also identified 20 new bugs in Python, Ruby, and PHP, many of which are severe memory corruptions. Moreover, we provide a comprehensive benchmark totaling 150 proof-of-concepts to improve interpreter security.<\/jats:p>","DOI":"10.1145\/3808111","type":"journal-article","created":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T17:06:14Z","timestamp":1782839174000},"page":"2328-2349","source":"Crossref","is-referenced-by-count":0,"title":["CrossFit: Demystifying VM Callback Bugs in Interpreters"],"prefix":"10.1145","volume":"3","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0003-7367-2131","authenticated-orcid":false,"given":"Chibin","family":"Zhang","sequence":"first","affiliation":[{"name":"EPFL, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-5865-6227","authenticated-orcid":false,"given":"Qiang","family":"Liu","sequence":"additional","affiliation":[{"name":"EPFL, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0001-5054-7547","authenticated-orcid":false,"given":"Mathias","family":"Payer","sequence":"additional","affiliation":[{"name":"EPFL, Lausanne, Switzerland"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,6,30]]},"reference":[{"key":"e_1_2_1_1_1","unstructured":"n. d.]. Clang Static Analyzer. https:\/\/2.zoppoz.workers.dev:443\/https\/clang-analyzer.llvm.org\/."},{"key":"e_1_2_1_2_1","unstructured":"PyRTFuzz\/Apispec\/PySpec\/StcSpec\/Pyspec\/Apispec_openai_generator.Py at Master \u2022 Awen-Li\/PyRTFuzz. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/awen-li\/PyRTFuzz\/blob\/master\/apispec\/PySpec\/StcSpec\/pyspec\/apispec_openai_generator.py."},{"key":"e_1_2_1_3_1","unstructured":"Python\/Typeshed: Collection of Library Stubs for Python with Static Types. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/python\/typeshed."},{"key":"e_1_2_1_4_1","unstructured":"Tunz\/Js-Vuln-Db: A Collection of JavaScript Engine CVEs with PoCs. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/tunz\/js-vuln-db."},{"key":"e_1_2_1_5_1","unstructured":"2019. PHP Remote Code Execution Vulnerability (CVE-2019-11043). https:\/\/2.zoppoz.workers.dev:443\/https\/blog.qualys.com\/producttech\/2019\/10\/30\/php-remote-code-execution-vulnerability-cve-2019-11043."},{"key":"e_1_2_1_6_1","unstructured":"2023. TIOBE Index. https:\/\/2.zoppoz.workers.dev:443\/https\/www.tiobe.com\/tiobe-index\/."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23412"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP"},{"key":"e_1_2_1_9_1","first-page":"199","volume-title":"Sys: A Static\/Symbolic Tool for Finding Good Bugs in Good (Browser) Code. In 29th USENIX Security Symposium (USENIX Security 20)","author":"Brown Fraser","year":"2020","unstructured":"Fraser Brown, Deian Stefan, and Dawson Engler. 2020. Sys: A Static\/Symbolic Tool for Finding Good Bugs in Good (Browser) Code. In 29th USENIX Security Symposium (USENIX Security 20). 199-216."},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00071"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3387904.3389253"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2023.24290"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23263"},{"key":"e_1_2_1_14_1","volume-title":"Precise and Scalable Detection of Use-after-Compacting- Garbage-Collection Bugs. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Han HyungSeok","year":"2021","unstructured":"HyungSeok Han, Andrew Wesie, and Brian Pak. 2021. Precise and Scalable Detection of Use-after-Compacting- Garbage-Collection Bugs. In 30th USENIX Security Symposium (USENIX Security 21). 2059-2074."},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/3428334"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3484823"},{"key":"e_1_2_1_17_1","first-page":"445","volume-title":"Proceedings of the 21th USENIX Security Symposium","author":"Holler Christian","year":"2012","unstructured":"Christian Holler, Kim Herzig, and Andreas Zeller. 2012. Fuzzing with Code Fragments. In Proceedings of the 21th USENIX Security Symposium, Bellevue, WA, USA, August 8-10, 2012, Tadayoshi Kohno (Ed.). USENIX Association, 445-458."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER56733.2023.00024"},{"key":"e_1_2_1_19_1","first-page":"2613","volume-title":"Montage: A Neural Network Language Model- Guided JavaScript Engine Fuzzer. In 29th USENIX Security Symposium, USENIX Security 2020","author":"Lee Suyoung","year":"2020","unstructured":"Suyoung Lee, HyungSeok Han, Sang Kil Cha, and Sooel Son. 2020. Montage: A Neural Network Language Model- Guided JavaScript Engine Fuzzer. In 29th USENIX Security Symposium, USENIX Security 2020, August 12-14, 2020, Srdjan Capkun and Franziska Roesner (Eds.). USENIX Association, 2613-2630."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88806-0_16"},{"key":"e_1_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00067"},{"key":"e_1_2_1_22_1","volume-title":"RBS: Ruby Signature. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/ruby\/rbs. Ruby type signature language and tools.","author":"Team Ruby Core","year":"2023","unstructured":"Ruby Core Team. 2023. RBS: Ruby Signature. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/ruby\/rbs. Ruby type signature language and tools."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460319.3464814"},{"key":"e_1_2_1_24_1","first-page":"2471","volume-title":"Detecting Kernel Refcount Bugs with Two- Dimensional Consistency Checking. In 30th USENIX Security Symposium (USENIX Security 21)","author":"Tan Xin","year":"2021","unstructured":"Xin Tan, Yuan Zhang, Xiyu Yang, Kangjie Lu, and Min Yang. 2021. Detecting Kernel Refcount Bugs with Two- Dimensional Consistency Checking. In 30th USENIX Security Symposium (USENIX Security 21). 2471-2488."},{"key":"e_1_2_1_25_1","unstructured":"SSD Secure Disclosure technical team. 2020. SSD Advisory -PHP SplDoublyLinkedList UAF Sandbox Escape. https:\/\/2.zoppoz.workers.dev:443\/https\/ssddisclosure.com\/ssd-advisory-php-spldoublylinkedlist-uaf-sandbox-escape\/."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.23"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690336"},{"key":"e_1_2_1_28_1","first-page":"3655","volume-title":"Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs. In 32nd USENIX Security Symposium (USENIX Security 23)","author":"Xu Jianhao","year":"2023","unstructured":"Jianhao Xu, Kangjie Lu, Zhengjie Du, Zhu Ding, Linke Li, Qiushi Wu, Mathias Payer, and Bing Mao. 2023. Silent Bugs Matter: A Study of Compiler-Introduced Security Bugs. In 32nd USENIX Security Symposium (USENIX Security 23). 3655-3672."},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3423340"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1993316.1993532"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","unstructured":"Chibin Zhang. 2026. Artifact for FSE26 CrossFit: Demystifying VM Callback Bugs in Interpreters. doi:10.5281\/zenodo. 19732538 10.5281\/zenodo.19732538","DOI":"10.5281\/zenodo"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3708821.3710818"}],"container-title":["Proceedings of the ACM on Software Engineering"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3808111","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,30]],"date-time":"2026-06-30T18:40:20Z","timestamp":1782844820000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3808111"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6,30]]},"references-count":32,"journal-issue":{"issue":"FSE","published-print":{"date-parts":[[2026,6,30]]}},"alternative-id":["10.1145\/3808111"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3808111","relation":{},"ISSN":["2994-970X"],"issn-type":[{"value":"2994-970X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,6,30]]}}}